[Freeipa-users] How to check IPA <--> AD trust from command line

Ben .T.George bentech4you at gmail.com
Tue Jan 6 16:52:20 UTC 2015


Hi

I Tried on IPA server and below is my output:

[root at kwtpocpbis01 ~]# kinit adm-ben.george at kwttestdc.com
Password for adm-ben.george at kwttestdc.com:
kinit: KDC reply did not match expectations while getting initial
credentials

how can i troubleshot this issue.?

Thanks & Regards,
Ben


On Tue, Jan 6, 2015 at 6:41 PM, Sumit Bose <sbose at redhat.com> wrote:

> On Tue, Jan 06, 2015 at 07:19:15AM -0700, Rich Megginson wrote:
> > On 01/05/2015 08:35 PM, Ben .T.George wrote:
> > >
> > >Hi LIst,
> > >
> > >how to check IPA <-> Active directory trust relationship . i just want
> to
> > >confirm my ipa server is working fine.
> >
> > On an IPA server or client machine:
> > $ kinit adusername at ADDOMAIN.COM
> > Password: aduserpassword
> >
> > If there are no AD users yet, you can try with
> administrator at ADDOMAIN.COM
> > assuming you have the AD admin password.
>
> Additionally you have to check if the AD user can get a ticket for an IPA
> service e.g. after calling kinit with the AD user call
>
> kvno ldap/ipaserver.ipa.domain at IPA.DOMAIN
>
> bye,
> Sumit
>
> >
> > >
> > >Regards,
> > >Ben
> > >
> > >
> >
>
> > --
> > Manage your subscription for the Freeipa-users mailing list:
> > https://www.redhat.com/mailman/listinfo/freeipa-users
> > Go To http://freeipa.org for more info on the project
>
> --
> Manage your subscription for the Freeipa-users mailing list:
> https://www.redhat.com/mailman/listinfo/freeipa-users
> Go To http://freeipa.org for more info on the project
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://listman.redhat.com/archives/freeipa-users/attachments/20150106/6b957c26/attachment.htm>


More information about the Freeipa-users mailing list